CVE-2022-4047: Return Refund and Exchange For WooCommerce < 4.0.9 - Unauthenticated Arbitrary File Upload
The Return Refund and Exchange For WooCommerce WordPress plugin before 4.0.9 does not validate attachment files to be uploaded via an AJAX action available to unauthenticated users, which could allow them to upload arbitrary files such as PHP and lead to RCE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-4047?
CVE-2022-4047 has a high severity rating due to the potential for remote code execution from unauthenticated users.
How do I fix CVE-2022-4047?
To fix CVE-2022-4047, update the Return Refund and Exchange for WooCommerce plugin to version 4.0.9 or later.
Who is affected by CVE-2022-4047?
Users of the Return Refund and Exchange for WooCommerce plugin on WordPress versions prior to 4.0.9 are affected by CVE-2022-4047.
What type of vulnerability is CVE-2022-4047?
CVE-2022-4047 is a file upload vulnerability that can lead to remote code execution.
Can unauthenticated users exploit CVE-2022-4047?
Yes, unauthenticated users can exploit CVE-2022-4047 to upload arbitrary files, potentially leading to remote code execution.